Organizational profiles: current versus target
Organizational Profiles require a company to document its current cybersecurity posture and define its desired future state using the NIST CSF Core. By comparing the "Current Profile" against the "Target Profile," an organization identifies security gaps to prioritize investments and risk reduction efforts.
What it means
In practice, this is a gap analysis exercise. The Current Profile acts as a baseline, detailing which cybersecurity outcomes are already being achieved and how they are implemented based on existing policies, tools, and processes. It provides a realistic snapshot of the organization's present security maturity.
The Target Profile represents the "ideal state" that aligns with the organization's risk appetite, business objectives, and legal or regulatory obligations. It does not necessarily mean implementing every single subcategory in the Framework, but rather selecting those that are most critical to the specific mission of the organization.
The difference between these two profiles creates a roadmap. This process transforms the NIST CSF from a static list of suggestions into a customized strategic plan for improving cybersecurity resilience over time.
How to meet it
- Inventory existing security controls and map them directly to the NIST CSF 2.0 Functions, Categories, and Subcategories to create your Current Profile.
- Conduct a risk assessment to determine which outcomes are most critical to your business operations and regulatory requirements.
- Define a Target Profile by selecting the specific subcategories that must be achieved to reach an acceptable level of residual risk.
- Perform a side-by-side comparison (Gap Analysis) between the Current and Target profiles to identify missing or underperforming controls.
- Develop a prioritized action plan or roadmap that outlines the projects, budget, and timelines required to move from the current state to the target state.
- Review and update both profiles annually or whenever significant changes occur in the business environment or threat landscape.
Evidence an auditor asks for
- A completed Current Profile document (often a spreadsheet) mapping existing capabilities to CSF subcategories.
- A documented Target Profile that justifies why specific outcomes were prioritized based on risk appetite.
- A Gap Analysis report explicitly detailing the deficiencies between the current and target states.
- A strategic roadmap or Project Plan showing scheduled improvements designed to close those identified gaps.
Common pitfalls
- Aiming for "perfection" by setting a Target Profile that requires every single CSF subcategory, resulting in an unfunded and unrealistic goal.
- Treating profiles as one-time checkboxes rather than living documents that evolve with the threat landscape.
- Creating a Target Profile without input from business leadership, leading to security goals that conflict with operational needs.